CVE-2007-1560

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/03/2007
Last modified:
09/04/2025

Description

The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemon crash) via crafted TRACE requests that trigger an assertion error.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:squid:squid:2.6.stable1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.6.stable2:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.6.stable3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.6.stable4:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.6.stable5:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.6.stable6:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.6.stable7:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.6.stable8:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.6.stable9:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.6.stable10:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.6.stable11:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools